Vulnerabilities > Moodle > Moodle > 3.5.11

DATE CVE VULNERABILITY TITLE RISK
2020-11-19 CVE-2020-25701 Incorrect Authorization vulnerability in multiple products
If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method.
network
low complexity
moodle fedoraproject CWE-863
5.3
2020-11-19 CVE-2020-25700 SQL Injection vulnerability in multiple products
In moodle, some database module web services allowed students to add entries within groups they did not belong to.
network
low complexity
moodle fedoraproject CWE-89
6.5
2020-11-19 CVE-2020-25699 Incorrect Authorization vulnerability in multiple products
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course.
network
low complexity
moodle fedoraproject CWE-863
7.5
2020-11-19 CVE-2020-25698 Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course.
network
low complexity
moodle fedoraproject
7.5
2020-05-21 CVE-2020-10738 Improper Input Validation vulnerability in Moodle
A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions.
network
low complexity
moodle CWE-20
8.8
2020-02-17 CVE-2020-1692 Unspecified vulnerability in Moodle
Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.
network
low complexity
moodle
6.5
2020-02-11 CVE-2019-18210 Cross-site Scripting vulnerability in Moodle
Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter.
network
moodle CWE-79
3.5
2019-06-26 CVE-2019-10154 Improper Access Control vulnerability in Moodle
A flaw was found in Moodle before versions 3.7, 3.6.4.
network
low complexity
moodle CWE-284
5.0
2019-03-26 CVE-2019-3852 Unspecified vulnerability in Moodle
A vulnerability was found in moodle before version 3.6.3.
network
low complexity
moodle
4.0